Nostra Exploit: Oracle Manipulation Leads to $3.5 Million in Unauthorized Loans
Over 8,300 times in just eleven minutes, Nostra’s own price oracle severely inflated the value of its native token within its lending platform, according to independent analysis.
On the morning of the incident, third-party sources estimated NSTR’s market cap at approximately $550,000. Despite this, a single address managed to secure about $3.5 million worth of ETH, STRK, USDC, USDT, WBTC, and DAI using the artificially boosted value, a figure also acknowledged by Nostra.

This incident did not involve flash loans or reentrancy vulnerabilities. Instead, the attacker established a low-liquidity, attacker-controlled pool. A price feed derived from GeckoTerminal appears to have been incorporated into Pragma’s pricing mechanism, and Nostra’s oracle then averaged this manipulated data with a legitimate source, rather than discarding such a large discrepancy.
According to one reconstruction, the NSTR posted as collateral for the loan was genuinely worth around $421—far less than the millions borrowed against it.
Nostra publicly announced the exploit after pausing its lending market, promising further details in a forthcoming post-mortem.
The protocol had previously reported similar oracle-based vulnerabilities: In March 2025, Nostra halted borrowing for two tokens after its oracle overstated their value by about threefold, admitting it had no backup pricing source. While the specific tokens and technical details differed, the underlying risk of oracle failure remained.
Eighteen months later, the same type of risk enabled a much larger exploit.
Did Nostra address the initial warning, or was it simply logged and left unremedied?
Credit: Sprunky, BeinCrypto, Nostra, Blocksec, CoinTelegraph, PeckShield, CertiK, BlockSec, AMLBot, GoPlus Security, Pragma, DBCrypto, DefiLlama, Vesu
Nostra revealed its own security incident on September 17th.
An official statement confirmed that manipulation of the NSTR price oracle allowed a user to borrow about $3.5 million against inflated collateral. Lending, borrowing, withdrawals, and liquidations were all halted as the money market was paused.
Nostra’s disclosure came before public alerts from PeckShield, CertiK, and other security analysts.
However, the timeline of when the manipulation was detected, when the pause was executed, or whether outside researchers had already flagged the transactions remains unclear.
It took about eleven hours before public forensic reviews started.
CertiK soon confirmed the price manipulation, and shortly after shared details on fund distribution: $1.55 million stayed on Starknet, while $1.93 million had been transferred to Ethereum.
BlockSec’s Phalcon platform described the technical sequence: the attacker set up an NSTR/SolvBTC pool with minimal liquidity, manipulated the price with a small trade, and each step was referenced with a transaction hash.
Sprunky, an independent researcher, reconstructed the price manipulation: first, a correct AVNU quote; then, after about ten minutes, a manipulated GeckoTerminal-derived quote. Sprunky’s analysis measured the difference between the true and manipulated NSTR/ETH price at approximately 8,306 times.
By the next day, AMLBot reported tracing the movement of funds via Near Intents, CCTP, and LayerZero OFT, with around $1.6 million still at the Starknet address.
Nostra’s public disclosure preceded the comprehensive forensic threads that later detailed the exploit.
The attacker's strategic accumulation of NSTR took place months ahead of the attack, though there was no clear way to identify the wallet as a threat in advance.
The exploit did not require prolonged undetected preparation.
On the critical day, all that was needed was for the attacker-crafted pool to be accepted as a valid price source for NSTR collateral.
This raises a key question: why did Nostra’s systems accept the manipulated pool’s price as legitimate collateral value?
Oracle Design and the Flawed Price Calculation
The attacker did not need to compromise Pragma’s code. Instead, they simply introduced a convincing enough false input that, when averaged with a legitimate price, still resulted in a collateral value high enough to enable large borrowing.
BlockSec’s Phalcon analysis outlines the steps:
- The attacker created a new NSTR/SolvBTC pool, adding about 1.5 SolvBTC solely on one side, away from regular trading activity.
- This addition influenced GeckoTerminal’s pool-selection, causing it to use the new, thin pool as a reference for NSTR’s price.
- A small purchase in this manipulated pool rapidly increased the reported price from fractions of a cent to over $99.
Pool creation:
0x741af6efcc55165e89f7ef0b8ebad7e87efeaa8daa3b60dddd62d5dcacae69d
Pragma’s oracle aggregation method is intended to mitigate the impact of individual manipulated feeds. It determines a value for each source using the median of submitted prices, and the protocol decides how to combine these results.
Pragma’s guidance calls for a minimum of three price sources, with additional checks for freshness and asset-specific risk thresholds.
On the day of the incident, only two sources were available: an AVNU quote at about $0.00596 and a manipulated GeckoTerminal quote of approximately $99.02.
With no third input, the system produced a midpoint around $49.52.
Sprunky’s analysis concluded this was the final collateral value used by Nostra.
The transaction used an NSTR/ETH collateral rate of 0.02032399, compared to the real market rate of 0.00000244689, an 8,306x inflation.
This discrepancy was independent of ETH’s USD value at the time.
Pragma’s post-incident update confirmed the two-source issue. NSTR had been classified as high-risk due to limited liquidity and sources, and Pragma had previously raised these concerns with Nostra. Gate.io had been removed as a source at Nostra’s request due to liquidity and manipulation worries, which left the system with few sources.
While removing a weak source may have been justified, the core issue was that a feed with just two sources still allowed borrowing to proceed at a grossly inflated valuation.
Pragma’s guidance suggests that enforcing a three-source minimum would have prevented this incident. Pragma’s review also found no calculation errors in decimals or medians.
In other words, the system worked as configured, but the configuration was flawed.
Calculating the real collateral value highlights the problem. Sprunky estimates that roughly 70,686 NSTR used as collateral was worth about $421 at market rates, yet was used to back $3.5 million in loans—over $8,000 borrowed per $1 of real collateral.
Independent analysis supports these numbers, clarifying why the attacker needed so little genuine collateral.
With NSTR’s circulating value at around $550,000 that day, the borrowed amount exceeded six times the token’s entire market cap—a striking but not strictly solvency-related comparison.
Public records show that a large gap between two price feeds was accepted, and with no third source, a highly inflated collateral valuation was used to authorize millions in borrowing.
It remains unclear what, if any, safeguards Nostra had to prevent such outcomes.
We do not yet know what controls Nostra placed on NSTR’s price and collateralization, or why the system allowed borrowing at the calculated price. Further details are expected in their promised post-mortem.
All components may have followed their configuration, which brings attention to the adequacy of that configuration.
If a protocol can average $0.006 and $99 to determine a collateral value, the root problem lies beyond just the manipulated pool; it is an oracle structure that failed to question whether the result made economic sense.
The system did not test for economic plausibility.
After the value was accepted, who verified the movement of the $3.5 million it unlocked?
Step-by-Step: The Borrowing and Exit Path
BlockSec’s Phalcon reconstruction details the relevant on-chain transactions, with transaction hashes open for review.
The sequence involves:
- Creation of the manipulated pool
- The price-spiking trade
- The two oracle entries recorded by Pragma
- Each borrow transaction for the different assets
Pool creation (NSTR/SolvBTC pool, seeded with about 1.5 SolvBTC): 0x741af6efcc55165e89f7ef0b8ebad7e87efeaa8daa3b60dddd62d5dcacae69d
Trade that spiked the price (small trade in the thin pool, boosting NSTR to ~$99): 0x772e73613ffbc845508377fc6ded1137f60ad730aecb2b7c18a2978a84a6ac1
AVNU oracle update (5:37 UTC, NSTR price $0.00596118): 0x1d33ab3d3ff72c82d7b1b6b317d28eff38abd03c0f084985c30b14859328b7f
GeckoTerminal oracle update (5:47 UTC, manipulated NSTR price $99.02439975): 0x6bc9b41bce2b6c08639c16790af064efafa15890c1ebf8cc72df99a577a1cf1
ETH borrow (939.30 ETH, ~$2,297,659.30 at $2,446.14 per ETH): 0x2460fde607d09f2434d1b4e6d4089c6e1f459f4ce70ba2853d3a37547cdf00e
STRK borrow (28,272,985.90 STRK, ~$819,250.48 at $0.02897644): 0x79005742a8f7fe443a4a0d444f053ba06a49a15d558662404aa894479ddb820
USDC.e borrow (113,661 USDC.e, ~$113,648.39): 0x34bb10618939a14db2f613acad1d63bfbfb96908fdb6a6f2fb65a07af6a200a
USDT borrow (84,377 USDT, ~$84,365.93): 0x61eacbd4f4fc4230a6e3b204ff0cdc26939db0663f3bec1418f51b79c5b0647
WBTC borrow, first (2 WBTC, ~$152,742.00 at $76,371): 0x373be1419cb2b5d0ef7fc684070857dbe88235e81c29fbe5d8e053640968fb4
DAI borrow (29,078 DAI, ~$29,264.11): 0x5a8a94a14cc2950f81f5409c992218fa25827b4e2b9ec9a1d4b33bd623bc54d
WBTC borrow, second (0.88 WBTC, ~$67,206.48 at $76,371): 0x439ab7565b07299ad1f6cb57ee10e9f47dd80b1b98a4bac2ba696a0934ce95
In total, about $3.56 million was borrowed across six assets, in line with Nostra’s own reported numbers.
The attacker then liquidated these assets via approximately 80 transactions on AVNU, Ekubo, and JediSwap, as documented by GoPlus Security.
GoPlus Security describes a two-phase exit: sales on Starknet, then transfers to intermediary wallets, and finally off-chain movement through NEAR Intents.
Nostra borrowing transactions were linked to this Starknet address: 0x06d48ef7ab62c26e3ef1987c322096cd508e9034c82048783a6b438fc1344bc3
Price manipulation was attributed to this account: 0x2d9fb4edec9d5c015c43514ca5a309aab1b2638c3a45ad750d09ee971d0da23
After DEX trades, 1.2 million STRK went to this transit account: 0x0285b4bf99e227c4baed7f9a8c7c673771fe0b75e897f7350729e3e13021321d
Another 1.0 million STRK was routed via this address: 0x074f5318f8d60ad0832068dc0430d0a0e2f9dd0c2e710fb8c032945a3804b57e
Both intermediary accounts moved funds through NEAR Intents, according to GoPlus.
Funds were consolidated in this Ethereum wallet: 0xa059aaab82773caf622de9d9a0f2dbf9aa7f3c37
The attack route was as follows: Nostra loan → asset sales (AVNU/Ekubo/JediSwap) → two Starknet intermediary wallets → NEAR Intents → Ethereum consolidation.
While the asset flows are clear, the larger impact on Nostra’s protocol and user funds became the next concern.
The transactions can be traced, but what consequences did the exploit have on the protocol and its stakeholders?
When Price Oracles Become Vulnerabilities
Nostra’s disclosure of the $3.5 million unauthorized borrowing did not stop users from withdrawing funds.

The consequences were significant: Nostra’s total value locked dropped from around $4.15 million to about $743,000 between September 16 and 18, per DefiLlama, while NSTR’s market cap was around $546,751.
The protocol’s initial statement confirmed all lending, borrowing, withdrawals, and liquidations were suspended, with the extent of losses and recovery still undetermined, and a full post-mortem promised.
A warning was issued not to trust unsolicited messages or wallet connection requests related to recovery—a critical reminder as phishing activity tends to spike during incident responses.
Nostra was not the only protocol affected by oracle issues in September. On September 4, a price-feed malfunction in the oracle used by Vesu led to several assets being mispriced at about half their actual value for 109 seconds.
This error caused 47 liquidations across 42 borrower wallets in seven pools.
The Vesu incident was not the result of manipulation, but a technical price-publishing mistake.
Vesu later reported it had recovered 95% of affected value at current prices, or 93% at incident-time prices (about $1.33 million recovered out of $1.395 million in claims).
The causes differed: Vesu’s issue stemmed from a publication error, while Nostra’s was due to deliberate market manipulation.
Yet, both highlight a systemic vulnerability: when protocols rely on oracles to determine collateral or liquidation thresholds, a faulty value can have immediate and severe consequences, sometimes before any intervention is possible.
The month was already costly for DeFi platforms. Including Nostra’s incident, DefiLlama recorded over $342 million lost to exploits in September, with the Liquid Network incident comprising about $320 million of that.
Nostra claims to have been audited by Trail of Bits, Cairo Security Clan, and Salus, but does not provide direct links to reports, their dates, or details.
The failure appears to have involved the price-data path into the lending contracts, particularly the external data source and oracle aggregation, not necessarily the core lending code.
Pragma’s documentation and audits concern the oracle structure and on-chain contracts, but do not clarify how market data providers chose which NSTR pool to reference.
GeckoTerminal’s API documentation shows that multiple pool prices can be retrieved for a token, but does not specify what, if any, safeguards or thresholds were in place to prevent such manipulation.
The key issue is not the existence of audits, but whether the protocol’s risk management properly considered the reliability of off-chain price feeds.
When code is designed to defer to an oracle, who ensures the oracle is trustworthy?
It was not the attacker’s pool alone that enabled the exploit, but a sequence of systems that accepted and amplified the manipulated price.
Fundamentally, the risk design allowed a manipulated, low-liquidity market to determine collateral values at a scale far beyond reasonable limits.
This was not without precedent. In March 2025, Nostra reported that its price feeds for xSTRK and sSTRK had been overstated by about threefold, with no backup oracle available.
In August 2025, Nostra’s post-mortem described an incident where Pragma’s xSTRK feed became non-functional, resulting in $14,212 in undercollateralized loans, which Nostra Labs covered.
Pragma’s statement regarding the recent NSTR event reiterates the risk: NSTR was treated as high-risk due to limited sources and liquidity, and these concerns had been raised with Nostra. Gate.io was removed as a source at Nostra’s request due to similar concerns.
Pragma’s guidance requires at least three price sources, and states that this standard would have prevented the exploit, but only two sources were used at the time.
Earlier incidents differed technically: March involved inflated prices, August a non-functional feed, September market manipulation in an illiquid NSTR pool.
However, all reveal a recurring risk: exposure to unreliable external price data affecting collateralization, rather than a completely unpredictable failure.
Nostra’s eventual post-mortem will need to address not only the manipulated pool, but also its approach to evaluating thin-liquidity collateral, policies for missing or divergent price feeds, the rationale for keeping NSTR eligible for borrowing, and its plan for resolving losses and outstanding claims.
The manipulated pool was just a tool; the real question is whether Nostra's risk model was robust enough to prevent such an outcome.
Get new scam files the moment we publish them — usually 2–3 emails a week.